Bug #53664
openradosgw-admin subuser create can modify AK-SK pair of other subuser
0%
Description
first create subuser sub-1:
@radosgw-admin subuser create --uid root-user --subuser sub-1 --key-type s3
{
"user_id": "root-user",
"display_name": "root-user",
"email": "",
"suspended": 0,
"max_buckets": 1000,
"subusers": [
{
"id": "root-user:sub-1",
"permissions": "<none>"
}
],
"keys": [
{
"user": "root-user",
"access_key": "3MAYVX4DGJ5635K18YHN",
"secret_key": "vdX3sFVKxdqgz99wtd3Yf3wt7N74d4z2JXLFPMU5"
},
{
"user": "root-user:sub-1",
"access_key": "5ZJFAS72DZ0UWS1FVRAC",
"secret_key": "ytEDATJmzsXrNxwQ2arqKU4qiPj5hAffbAvkq11d"
}
],
"swift_keys": [],
@
then create subuser sub-2, but modfiy sub-1's AK-SK pair:
@radosgw-admin subuser create --uid root-user --subuser sub-2 --access-key "5ZJFAS72DZ0UWS1FVRAC" --secret test --key-type s3
{
"user_id": "root-user",
"display_name": "root-user",
"email": "",
"suspended": 0,
"max_buckets": 1000,
"subusers": [
{
"id": "root-user:sub-1",
"permissions": "<none>"
},
{
"id": "root-user:sub-2",
"permissions": "<none>"
}
],
"keys": [
{
"user": "root-user",
"access_key": "3MAYVX4DGJ5635K18YHN",
"secret_key": "vdX3sFVKxdqgz99wtd3Yf3wt7N74d4z2JXLFPMU5"
},
{
"user": "root-user:sub-1",
"access_key": "5ZJFAS72DZ0UWS1FVRAC",
"secret_key": "test"
}
],
"swift_keys": [],@
Updated by Casey Bodley about 2 years ago
- Status changed from New to Fix Under Review
- Pull request ID set to 44358